CVE-2014-1303: Apple Safari

High severity, CVSS 10.0. EPSS: 34.8% chance of exploitation in the next 30 days.

Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by Liang Chen during a Pwn2Own competition at CanSecWest 2014.

Affected products

  • Apple Safari: version 7.0.2 only

Published 2014-03-26. Last modified 2026-06-17.